CVE-2023-50708: yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
Impact What kind of vulnerability is it? Who is impacted?
Original Report:
> The Oauth1/2 "state" and OpenID Connect "nonce" is vulnerable for a "timing attack" since it's compared via regular string > comparison (instead of Yii::$app->getSecurity()->compareString()).
Affected Code:
1. OAuth 1 "state"
https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b54e69695ff/src/OAuth1.php#L158
3. OAuth 2 "state" https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b54e69695ff/src/OAuth2.php#L121
4. OpenID Connect "nonce" https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b54e69695ff/src/OpenIdConnect.php#L420
Patches Has the problem been patched? What versions should users upgrade to?
TBD: Replace strcmp with Yii::$app->getSecurity()->compareString()).
Workarounds Is there a way for users to fix or remediate the vulnerability without upgrading?
not as far as I see.
References Are there any links users can visit to find out more?
Other sources
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth1/2 state and OpenID Connect nonce is vulnerable for a timing attack since it is compared via regular string comparison (instead of Yii::$app->getSecurity()->compareString()). Version 2.2.15 contains a patch for the issue. No known workarounds are available.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50708?
The severity of CVE-2023-50708 is medium due to the potential for timing attacks on OAuth1/2 state and OpenID Connect nonce.
How do I fix CVE-2023-50708?
To fix CVE-2023-50708, upgrade yiisoft/yii2-authclient to version 2.2.15 or later.
Which versions are affected by CVE-2023-50708?
CVE-2023-50708 affects all versions of yiisoft/yii2-authclient up to and including 2.2.14.
What types of attacks does CVE-2023-50708 expose to?
CVE-2023-50708 exposes applications to timing attacks that can compromise the security of OAuth and OpenID implementations.
Is there a workaround for CVE-2023-50708?
There is no specific workaround for CVE-2023-50708; the recommended action is to upgrade the affected software.